Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - trdeal

#1
I have a backup firewall which was running 27.6 (and not been internet connected until tonight since the upgrade to 26.7) with the original firewall rules when I update it to 27.6.4_1 this evening the process completed successfully and all the rules with the aliases worked correctly, absolutely no issues.
However I still restored the backup from this morning to both firewalls would be running the same config.
#2
Hi,

Checking the DNS Server rule and the cloned NTP server rule which I modified the rules were identical in terms of the options selected.
Even when I tried manually to recreate the DNS Server rule it still did not work, which is why I tried cloning the NTP Rule and modifying it and found that it worked. Do not know if it was part of the process when I imported the rules after the upgrade, so it looked as if it was a rule issue rather than an alias issue but I did create all new aliases which were used in the original rule before replacing to get a working solution.
#3
Checked the !DNS Server rule and it is working correctly. Not sure what happened to the original DNS Server but it has been deleted as the new rule is working
#4
Hi,
I found a workaround that has solved my problem and works after a reboot.  After disabling my allow all rule. I cloned the NTP Server rule which worked for UDP traffic on port 123 and added the DNS Server alias and changed the traffic to UDP/TCP and port from 123 to 53, then moved it in front of the old DNS Server rule. After establishing the rule worked I removed the NTP Server host alias from the rule, applied changed, monitored traffic then rebooted, rule continued to work after reboot.
Just need to the check the !DNS Server rule blocking internal clients is working correctly.
#5
Question "Did you hit apply in both the Alias page and the Rules page?"
Response "Yes, after every time I created an Alias. Just in case I went back to the Aliases page pressed apply then disabled my allow all rule making sure I have pressed apply and like before the DNS Server port 53 traffic is being blocked then had to re-enabled my allow all rule."

I recreated the DNS Host Alias objects as the original HOST alias was not working.

What I have now tried:
  1. Cloned DNS Server TCP/UDP access to rule anywhere where destination is Port 53 and disabled original rule
  2. Changed cloned DNS Server rule still TCP/UDP access to anywhere but using any port .................................. rule still would not work
  3. Changed cloned DNS Server rule so source changed from DNS Servers to dns, dns2, dns3 to anywhere using any port  .... rule still would not work

Interestingly the NTP Server alias group with a UDP access to anywhere where destination port 123 does work.

DNS Server Host alias contains dns1, dns2, dns3
NTP Server Host alias contains dns1, dns2, dns3
#6
Upgraded to 26.7.3_11 today and found that a Host alias in a rule which used Any protocol to Any destination did actually work.
However, a Host Alias in a rule with Protocol set to TCP/UDP and source the Host Aliases amd any destination but with a destination port of 53 (ie my DNS server rule) continues to be ignored so hits the default deny rule.
#7
Updated to 26.7.3_8 today, after reboot disabled the general allow all rule so all my rules with host aliases will be processed and all the DNS Servers traffic immediately started being blocked again. Had to re-enable my allow all rule.
#8
Upgraded to 27.7.2_2 yesterday still problems with host aliases not working in firewall rules, also noted that my acme certificate update process has failed.

Correction the Acme Ceritificate issue was a problem with an upstream router which is now fixed.
#9
Upgraded to 26.7.2 this evening, disabled my allow all traffic rule and immediately the DNS servers DNS queries were being blocked.
The current single DNS_NTP_Server alias which consisted of each server IPv4 and IPv6 address was replaced.
Each DNS server had a host alias created consisting of its IPv4 and IPv6 address, then a DNS_Server host alias was created consisting of each DNS server host alias. Editted the existing firewall rules to replace the old DNS_Svr host alias with the new DNS_Server Host alias. Disabled my allow any rule, the DNS Server traffic was being blocked. Tried disabling the block !DNS_Server rule to see if the traffic would be allowed but it was still blocked, it is as though the DNS_Server all DNS traffic rule was being ignored.
#10
Looking at the forum post below, there was a suggestion that removing the underscore might be a resolution, tried removing all the underscrore characters from my aliases and applied the update but the problem remained.
#11
26.7 Series / Re: Firewall rules and aliases.
August 02, 2026, 01:48:26 PM
Tried renaming all my aliases removing the underscore character but this made no difference the aliases still would not work.
#12
After upgrading to 26.7.1 none of the Aliases defined are working correctly in the Firewall rules eg

Internal_DNS_servers alias defined with multiple IPv4 and IPv6 addresses

Rule allows Internal_DNS_servers to make any DNS connection UDP/TCP

Later I have another rule which blocks non DNS servers from making external DNS queries

Rule blocks !Internal_DNS_servers to make any DNS connection UDP/TCP

My internal DNS servers are being blocked on the second rule

Tried upgrading to 26.7.1_1 no change in operation
#13
After upgrading to 26.7.1 a rule which allows internal DNS servers (defined as an Alias with IPv4 and IPv6 addresses) to perform UDP/TCP dns queries was ignored, however a later rule which used the invert of the DNS Servers Alias group which stopped non-DNS servers from making DNS queries blocked the DNS servers from performing DNS queries. Other rules using Aliases (with hosts identified) also did not work correctly.
#14
Hi,
I have a couple of old Dell Optiplex SFF PCs, a 7010 with an i5-3470 @3.2GHz and 3020 i5-3470@3.2Ghz (active and backup) both equipped with igb0 dual nic cards. I noticed that the 7010 had two 16x PCI slots so added two intel x550-t2 cards and replaced the 3020. With the 3020 I was getting latency issues connecting to the upstream router,  since swapping no issues.
When I ping the Opnsense (Optiplex 7010) LAN interface, WAN interface and the upstream router, the results are as follows 
LAN round-trip (ms)  min/avg/max/stddev = 0.128/0.149/0.288/0.028
WAN round-trip (ms)  min/avg/max/stddev = 0.139/0.166/0.299/0.036
Router round-trip (ms)  min/avg/max/stddev = 0.387/0.598/2.268/0.367 (not a direct connection but via 4 port switch)
I have ordered a second Dell Optiplex 7010 as a backup to current Optiplex 7010.
With reference to CPU utilisation it peaks around 15% with 15 clients accessing the internet

May 4th be with you - ordered refurbished Dell 7010 received refurbished Dell 9010 same specification i5-3470, pci-e buses so cards nic detected without problem 
#15
Hi,
The upstream router was the issue, it had a IPv6 Group object to route the IPv6 networks behind Opnsense but did not include the IPv6 object representing Opnsense FW. Updating the IPv6 Group object for routing and the problem was resolved. It was not DNS this time only human error :(

Run an Audit -> Connectivity
***GOT REQUEST TO AUDIT CONNECTIVITY***
Currently running OPNsense 26.1.1 (amd64) at Thu Feb  5 15:49:16 GMT 2026
Checking connectivity for host: pkg.opnsense.org -> 89.149.222.99
PING 89.149.222.99 (89.149.222.99): 1500 data bytes

--- 89.149.222.99 ping statistics ---
4 packets transmitted, 0 packets received, 100.0% packet loss
Checking connectivity for repository (IPv4): https://pkg.opnsense.org/FreeBSD:14:amd64/26.1
Updating OPNsense repository catalogue...
Fetching meta.conf: . done
Fetching data.pkg: .......... done
Processing entries: .......... done
OPNsense repository update completed. 929 packages processed.
All repositories are up to date.
Checking connectivity for host: pkg.opnsense.org -> 2001:1af8:5300:a010:1::1
PING(1548=40+8+1500 bytes) 2a02:8010:d00d:1:8395:9cef:ffaa:d122 --> 2001:1af8:5300:a010:1::1
1508 bytes from 2001:1af8:5300:a010:1::1, icmp_seq=1 hlim=56 time=23.762 ms
1508 bytes from 2001:1af8:5300:a010:1::1, icmp_seq=2 hlim=56 time=24.991 ms
1508 bytes from 2001:1af8:5300:a010:1::1, icmp_seq=3 hlim=56 time=24.747 ms

--- 2001:1af8:5300:a010:1::1 ping statistics ---
4 packets transmitted, 3 packets received, 25.0% packet loss
round-trip min/avg/max/stddev = 23.762/24.500/24.991/0.531 ms
Checking connectivity for repository (IPv6): https://pkg.opnsense.org/FreeBSD:14:amd64/26.1
Updating OPNsense repository catalogue...
Fetching meta.conf: . done
Fetching data.pkg: .......... done
Processing entries: .......... done
OPNsense repository update completed. 929 packages processed.
All repositories are up to date.
Checking server certificate for host: pkg.opnsense.org
depth=2 C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority
verify return:1
depth=1 C = AT, O = ZeroSSL, CN = ZeroSSL RSA Domain Secure Site CA
verify return:1
depth=0 CN = pkg.opnsense.org
verify return:1
DONE
***DONE***